Lynx is a ransomware operation that emerged in mid-2024 and is widely assessed as closely related to, or an evolution/rebrand of, INC Ransom. Reporting has linked Lynx to ransomware-as-a-service activity and to code lineage derived from the INC ransomware source, which was reportedly sold to multiple parties in 2024. Lynx has been associated with financially motivated extortion targeting organizations across multiple sectors, including construction, business services, healthcare, manufacturing, technology, logistics, education, and government-related environments. Lynx is known for double-extortion style operations in which network intrusion, data theft, and ransomware deployment are used to pressure victims. Observed post-compromise objectives include VPN compromise, access to domain controllers, acquisition of domain administrator privileges, persistence, and broad encryption impact across enterprise endpoints. Tradecraft associated with the broader Lynx/INC ecosystem includes use of valid accounts, credential stuffing, network sniffing, exploitation of known edge-device and remote-management weaknesses, lateral movement with living-off-the-land techniques, use of remote administration tooling, and data exfiltration prior to encryption. A significant 2026 development tied Lynx to the FortiBleed campaign, a large-scale credential-harvesting and initial-access operation targeting Fortinet FortiGate devices worldwide. Investigators reported that an operator associated with FortiBleed infrastructure was simultaneously logged into the ransom negotiation panels of both INC Ransom and Lynx, providing strong evidence that access harvested through FortiGate compromises was being operationalized for ransomware deployment. The same reporting assessed the FortiBleed operators as a likely Russian-speaking initial access broker organization with a structured team, and concluded that Lynx was a downstream beneficiary or participant in monetizing that access. Lynx has also been discussed alongside tooling and infrastructure overlaps seen in other ransomware investigations, including activity involving QDoor in at least one case. However, the highest-confidence characterization is that Lynx is a financially motivated ransomware actor operating in close relationship with INC Ransom, using established intrusion methods and extortion workflows rather than uniquely distinctive tradecraft. Known aliases and related designations primarily center on the lowercase form "lynx," while its most important relationship is its linkage to INC Ransom as a probable rebrand, successor, or closely affiliated subgroup.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the ransomware ecosystem linked to FortiBleed-derived access, with an operator observed logged into its negotiation panel and reporting tying FortiBleed to Lynx ransomware.
Ransomware group linked by researchers to the FortiBleed campaign, which harvested credentials from FortiGate devices and used that access in follow-on intrusions that in some cases ended with encryption of hundreds of systems.
Linked to the FortiBleed operation via attacker infrastructure containing active access to Lynx ransomware negotiation panels; the article says Lynx emerged in mid-2024 and is considered a rebrand of INC.
Linked to the FortiBleed campaign as one of the ransomware operations connected to stolen FortiGate credentials and follow-on ransomware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.